CVE-2008-2238

EUVD-2008-2235
Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
Affected Products (NVD)
VendorProductVersion
openofficeopenoffice.org
𝑥
≤ 2.4.1
openofficeopenoffice.org
2.0
openofficeopenoffice.org
2.0.2
openofficeopenoffice.org
2.0.3
openofficeopenoffice.org
2.0.4
openofficeopenoffice.org
2.1
openofficeopenoffice.org
2.2
openofficeopenoffice.org
2.2.1
openofficeopenoffice.org
2.3
openofficeopenoffice.org
2.3.1
openofficeopenoffice.org
2.4
openofficeopenoffice.org
2.4.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openoffice.org
dapper
Fixed 2.0.2-2ubuntu12.7
released
feisty
ignored
gutsy
Fixed 1:2.3.0-1ubuntu5.5
released
hardy
Fixed 1:2.4.1-1ubuntu2.1
released
intrepid
Fixed 1:2.4.1-11ubuntu2.1
released
openoffice.org-amd64
dapper
Fixed 2.0.2-2ubuntu12.7-2
released
gutsy
dne
hardy
dne
intrepid
dne
References